Apache TapestryÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-27850£©

Ðû²¼Ê±¼ä 2021-04-16

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2021-27850

ʱ    ¼ä

2021-04-16

Àà   ÐÍ

RCE

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

 

Apache TapestryÊÇÒ»ÖÖÓÃJava±àдµÄÃæÏò×é¼þµÄWebÓ¦ÓóÌÐò¿ò¼Ü ¡£¡£¡£¡£Tapestry¿ÉÒÔÔÚÈκÎÓ¦ÓóÌÐòЧÀÍÆ÷ÏÂÊÂÇ飬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔÇáËɼ¯³ÉËùÓкó¶Ë£¬£¬£¬£¬£¬£¬ÈçSpring£¬£¬£¬£¬£¬£¬HibernateµÈ ¡£¡£¡£¡£

2021Äê04ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬Apache Tapestry±»Åû¶±£´æÒ»¸öÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-27850£©£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉʹÓà ¡£¡£¡£¡£¸ÃÎó²îÈÆ¹ýÁËCVE-2019-0195µÄÐÞ¸´³ÌÐò£¨CVSSÆÀ·ÖΪ9.8£© ¡£¡£¡£¡£

ÔÚCVE-2019-0195ÖУ¬£¬£¬£¬£¬£¬Í¨¹ýʹÓÃclasspath×ʲúÎļþURL£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚclasspathÖÐÍÆ²âÎļþµÄ·¾¶£¬£¬£¬£¬£¬£¬È»ºóÏÂÔØ¸ÃÎļþ ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÇëÇó°üÀ¨HMACÃØÔ¿µÄURL http://localhost:8080/assets/something/services/AppModule.classÀ´ÏÂÔØÎļþAppModule.class ¡£¡£¡£¡£

CVE-2019-0195µÄÐÞ¸´Ê¹ÓÃÁ˺ÚÃûµ¥¹ýÂË£¬£¬£¬£¬£¬£¬Æä¼ì²éURLÊÇ·ñÒÔ¡°.class¡±¡¢¡°.properties¡±»ò¡°.xml¡±×îºó£¬£¬£¬£¬£¬£¬µ«ÕâÖÖºÚÃûµ¥¹ýÂË¿ÉÒÔͨ¹ýÔÚURL×îºóÌí¼Ó¡°/¡±À´Èƹý ¡£¡£¡£¡£µ±http://localhost:8080/assets/something/services/AppModule.class/ÔÚºÚÃûµ¥¼ì²éºó£¬£¬£¬£¬£¬£¬Ð±Ïß±»°þÀ룬£¬£¬£¬£¬£¬AppModule.classÎļþ±»¼ÓÔØµ½ÏìÓ¦ÖÐ ¡£¡£¡£¡£Õâ¸öÀàͨ³£°üÀ¨ÓÃÓÚ¶ÔÐòÁл¯µÄJava¹¤¾ß¾ÙÐÐÊðÃûµÄHMACÃØÔ¿£¬£¬£¬£¬£¬£¬ÔÚÖªµÀ¸ÃÃÜÔ¿µÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͿÉÒÔÇ©ÊðJavaС¹¤¾ßÁ´£¨ÀýÈçysoserialµÄCommonsBeanUtils1£©£¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ ¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

Apache Tapestry 5.4.5

Apache Tapestry 5.5.0

Apache Tapestry 5.6.2

Apache Tapestry 5.7.0

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶µ½ÒÔϰ汾£º

Apache Tapestry 5.4.0-5.6.2£¬£¬£¬£¬£¬£¬Éý¼¶µ½5.6.2»ò¸ü¸ß°æ±¾ ¡£¡£¡£¡£

Apache Tapestry 5.7.0£¬£¬£¬£¬£¬£¬Éý¼¶µ½5.7.1»ò¸ü¸ß°æ±¾ ¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://tapestry.apache.org/download.html

 

0x03 ²Î¿¼Á´½Ó

https://lists.apache.org/thread.html/r237ff7f286bda31682c254550c1ebf92b0ec61329b32fbeb2d1c8751%40%3Cusers.tapestry.apache.org%3E

https://nvd.nist.gov/vuln/detail/CVE-2019-0195

https://nvd.nist.gov/vuln/detail/CVE-2021-27850

 

0x04 ʱ¼äÏß

2021-04-14  Johannes MoritzÅû¶Îó²î

2021-04-16  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png